Privacy Policy
Last updated 14 August 2026
1. Who this covers#
This policy covers app.iotatron.xyz and the AIQuote application behind it, operated by AIQuote, Inc.
Two different kinds of people appear in it. You are the person with an account. Your customers are the companies whose cranes appear in the reports you upload — we hold their data because you gave it to us, and we act on your instructions in respect of it.
2. What we collect#
Your account. Name, email address and a password hash. We never store the password itself; it is hashed with scrypt, and a hash cannot be turned back into the original.
Your sessions. When you log in we store a session token, its expiry, the IP address the request came from and your browser’s user-agent string. This is what lets you stay logged in, and what would let us see that somebody else had logged in as you.
The workbooks you upload. The file is stored as you sent it, and the rows are also extracted into a database so the application can work with them. Between the two, that includes whatever your workbook contains — typically the customer name and site address on the cover sheet, the inspecting technician’s name, equipment and serial numbers, and every line the technician wrote.
What the models returned. For each finding you ask about, the part and labour estimate, the pages it cited, and the token counts and cost of the request.
3. What we do not collect#
There is no analytics, no advertising, no product telemetry and no third-party script of any kind on this site. Nobody is watching you scroll.
The site sets one cookie, and it holds your login session. It is not used to track you, it is not shared, and clearing it logs you out. There is no cookie banner because there is nothing to consent to.
4. What we send to the AI models#
Pricing a repair means asking a language model to search the web, so part of each finding does leave the platform. The set of fields is fixed in code and is exactly this:
- the section and item name — for example “Hoist(s) - Main / Holding Brake”
- the status the technician recorded, such as “Issue(s) Found”
- the technician’s note for that line, verbatim
- the hoist manufacturer, model, capacity and lifting medium
- the crane manufacturer and capacity
And, as deliberately, this is what is not sent:
- the customer name and site address
- the inspecting technician’s name
- the equipment or hoist serial number — it identifies which unit hangs on the bridge, not which part fits it, so it is excluded by design
- your name, your email, or anything else about your account
- the workbook file itself
The technician’s note is free text and we send it as written. If a technician types a person’s name, a phone number or a building’s address into a note, that text goes with the request. It is the one field we cannot filter without changing what the note means.
Requests are routed through OpenRouter to the models named on the report page, and those models run a web search to find part numbers and prices. Each provider applies its own policy to what it receives, and OpenRouter publishes theirs. We do not use your data to train models, and we do not sell it or share it with anyone else.
Answers are cached inside your organisation so the same defect on the next crane does not cost a second lookup. That cache is never shared between customers.
5. Who else touches it#
- Railway — hosting and the database. Everything described above lives there.
- OpenRouter, and the model providers it routes to — the finding fields listed in section 4, and nothing else.
- The search index and web pages the model consults during a lookup, which receive the search terms derived from those same fields.
That is the whole list. There is no email provider yet, which is why password reset does not work — see the note on that page.
6. How it is protected#
- Passwords are hashed with scrypt, never stored or logged in the clear.
- Traffic runs over HTTPS.
- Session cookies are signed with a secret that the application refuses to start without — there is no fallback default that could be guessed from the source.
- Every query for report data is scoped to your organisation, so a report id from another customer reads as missing rather than as forbidden.
No system is beyond compromise, and we would rather say so than imply otherwise. If you find a weakness, please write to [email protected] before disclosing it publicly.
7. How long we keep it#
Reports, uploaded files and stored answers are kept until you delete them or ask us to. There is no automatic expiry today, and we would rather tell you that than publish a retention schedule we do not actually run.
Deleting a report removes its file and its rows. Closing your account removes the account and the reports belonging to your organisation. Backups made by our hosting provider may hold a copy for a short period after that.
8. Your rights over this data#
Write to [email protected] and we will, within a reasonable period: tell you what we hold about you, give you a copy, correct anything wrong, or delete it.
Depending on where you or your customers are, there may be a legal right behind those requests rather than only our willingness — the GDPR in the EU and UK, and the CCPA in California, among others. We honour them either way, and we do not charge for it. We have never sold personal information and have no plans to.
9. Children#
This is a tool for industrial maintenance teams. It is not directed at children, and we do not knowingly collect data from anyone under 16.
10. Changes to this policy#
If this changes in a way that affects what we do with your data, we will update the date at the top and tell account holders by email before it takes effect — not quietly, and not retroactively.
11. Contact#
AIQuote, Inc. · 123 Industrial Way, Pittsburgh, PA 15201, United States.
[email protected] · +1 (555) 123-4567